A modern password policy favors long, unique passwords, password managers, and multifactor authentication over complex character rules and frequent forced changes.
Key takeaways
What to know before you act
- Current NIST guidance emphasizes length and screening against compromised passwords instead of complex composition rules.
- Routine forced password changes are discouraged unless there is evidence of compromise.
- A policy is only effective when paired with a password manager and multifactor authentication.
Why it matters
What business leaders should understand
Outdated policies can push employees toward predictable patterns and reused passwords. A clear, current policy improves security while reducing frustration and help-desk resets.
The right response should reflect your environment, data, vendors, risk, and operational priorities. Use this guide as a practical starting point, then validate important decisions with the people responsible for your technology, cybersecurity, legal obligations, and insurance coverage.
Learn how Meta IT Pro can help with cybersecurity services and security awareness training.
Related reading: 3 steps to a secure password and Phishing-resistant MFA and passkeys.
What a modern password policy should include
Keep the policy short and practical. Employees should be able to follow it without memorizing a page of rules.
- Minimum length: require a meaningful minimum and allow long passphrases.
- Screening: block passwords found in breach lists, dictionary words, and obvious patterns such as the company name.
- Uniqueness: never reuse a work password elsewhere.
- Storage: use the approved business password manager; no spreadsheets, sticky notes, or browser storage.
- MFA: required for email, remote access, financial systems, and administrators.
- Changes: required after suspected compromise, not on an arbitrary schedule.
- Shared accounts: avoided where possible; otherwise stored in a controlled vault with an owner.
Rolling it out without frustration
Explain why the rules changed. Many employees have been taught that frequent changes and symbols make passwords strong; replacing that habit requires a short explanation and good tools.
Configure technical controls to match the written policy—for example, password length and banned-password lists in Microsoft Entra ID or Google Workspace—so the system enforces what the document says. Review the policy annually and after significant incidents.
Practical action plan
Steps your business can take
Set a meaningful minimum length and allow long passphrases.
Screen new passwords against known breached and common passwords.
Provide a business password manager and require MFA for key systems.
Require changes when compromise is suspected rather than on a fixed schedule.
Recommended next steps
Continue from this article.
These pages expand the specific risks and decisions covered in this guide. Use them to move from general understanding to the service, tool, or related topic that best matches your next question.
Related guide
3 steps to a secure password
Share simple password habits with employees.
Explore nextRelated guide
Phishing-resistant MFA and passkeys
Pair the policy with stronger authentication.
Explore nextRelated guide
What is credential stuffing?
See why password reuse is so dangerous.
Explore nextService
Microsoft 365 management & security
Enforce password and MFA settings in Microsoft 365.
Explore nextWarning signs
Do not ignore these indicators
- Passwords must change every 30 or 60 days with no other controls
- Employees store passwords in spreadsheets or browsers
- The policy does not mention MFA or shared accounts
Frequently asked questions
Common questions, answered.
What should a modern password policy require?
A meaningful minimum length, screening against breached passwords, unique passwords, a password manager, and MFA.
Should passwords expire every 90 days?
NIST discourages routine forced changes; require changes when compromise is suspected.
Do we still need complexity rules?
Current guidance favors length and breached-password screening over composition rules.
How Meta IT Pro can help
Related services and practical next steps
Explore the services connected to this topic. These links provide more detail about scope, safeguards, support, and how to start a conversation with our team.
Authoritative references
Sources and further reading
These primary sources support the guidance in this article and provide additional technical or consumer information.
National Institute of Standards and Technology
NIST SP 800-63B: Digital Identity Guidelines—Authentication and Authenticator Management
NIST guidance on authenticator types, phishing resistance, and authentication assurance levels.
Cybersecurity and Infrastructure Security Agency
Use Strong Passwords
Guidance on long, random, unique passwords and the use of password managers.
Microsoft Learn
Security defaults in Microsoft Entra ID
Microsoft's baseline identity protections, including MFA registration and blocking legacy authentication.
Need help with your IT solution?
Get practical guidance from a local IT and cybersecurity team.
Meta IT Pro helps Massachusetts and Rhode Island businesses improve support, security, Microsoft 365, Google Workspace, networks, backup, recovery, and compliance readiness. Tell us what is not working - or what you want to improve - and we will help identify a sensible next step.
